Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill materially expands from storyboard planning into instructing the agent to execute terminal commands that call an external image-generation SaaS. That creates a real security boundary crossing: user prompts and local file paths may be sent off-host, and command execution is being normalized from within documentation. In this context, the issue is more dangerous because the skill explicitly frames the agent as able to run commands and prescribes operational behavior, increasing the chance of unintended data disclosure or unsafe tool use.
